CVE-2026-55863
published 2026-09-15CVE-2026-55863: motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0…
PriorityP335medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.50%
40.4th percentile
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the BaseHandler.auth() decorator, allowing an unauthenticated remote attacker to send requests to /action//. The endpoint can trigger snapshot, record_start, and record_stop actions. When an administrator has configured action scripts, the same endpoint can invoke PTZ controls, alarm actions, lighting actions, and other predefined commands, and configured remote motionEye cameras can allow server-side requests to the remote camera service. This issue is fixed in version 0.44.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| motioneye-project | motioneye | < 0.44.0 | 0.44.0 |
| motioneye_project | motioneye | >= 0 < 0.44.0 | 0.44.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/motioneye-project/motioneye/commit/0d5cb9c238a87447dae29812e5bf2ccf323cf3dchttps://github.com/motioneye-project/motioneye/pull/3332https://github.com/motioneye-project/motioneye/releases/tag/0.44.0https://github.com/motioneye-project/motioneye/security/advisories/GHSA-j67x-q29f-qcvvhttps://github.com/motioneye-project/motioneye/security/advisories/GHSA-j67x-q29f-qcvv
2026-09-15
Published